From d8e5c9f033dac9dd82759a85176cb7270a126d08 Mon Sep 17 00:00:00 2001 From: Raphael Michel Date: Thu, 26 Apr 2018 09:11:33 +0200 Subject: [PATCH] API: Fix insufficient permission check --- src/pretix/api/views/checkin.py | 1 + 1 file changed, 1 insertion(+) diff --git a/src/pretix/api/views/checkin.py b/src/pretix/api/views/checkin.py index 9541fbc5a..95ccefd4c 100644 --- a/src/pretix/api/views/checkin.py +++ b/src/pretix/api/views/checkin.py @@ -178,6 +178,7 @@ class CheckinListPositionViewSet(viewsets.ReadOnlyModelViewSet): filter_class = CheckinOrderPositionFilter permission = 'can_view_orders' + write_permission = 'can_change_orders' @cached_property def checkinlist(self):